
Floating Form Button Security & Risk Analysis
wordpress.org/plugins/floating-form-buttonThe "Floating Form Button" displayes an fixed contact button on the bottom right of the screen. It opens an small popup form above the butto …
Is Floating Form Button Safe to Use in 2026?
Generally Safe
Score 85/100Floating Form Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the "floating-form-button" plugin v0.9.1 exhibits a generally strong security posture. The absence of any detected dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly positive. Furthermore, the high percentage of properly escaped output signals good development practices for preventing cross-site scripting (XSS) vulnerabilities.
However, there are notable areas for improvement. The complete lack of nonce checks and capability checks across all entry points (though the attack surface is currently zero) represents a significant theoretical risk. If any new entry points are introduced in future versions without these security measures, the plugin would be highly vulnerable to CSRF and unauthorized action exploits. The taint analysis showing zero flows is also positive, but this is likely due to the limited scope or no sensitive data flows being present in this version.
The plugin's vulnerability history is exceptionally clean, with no recorded CVEs, which is a strong indicator of its past security. This, combined with the current static analysis findings, suggests a responsible development approach. The overall risk is low for the current version due to the lack of exploitable attack surface and known vulnerabilities, but the absence of fundamental security checks like nonces and capability checks presents a latent risk for future development.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- Some output not properly escaped
Floating Form Button Security Vulnerabilities
Floating Form Button Code Analysis
Output Escaping
Floating Form Button Attack Surface
WordPress Hooks 5
Maintenance & Trust
Floating Form Button Maintenance & Trust
Maintenance Signals
Community Trust
Floating Form Button Alternatives
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Side Menu Lite – Sticky Floating Side Menu
side-menu-lite
Create a sticky vertical sidebar menu that enhances navigation and highlights important links on your website.
Button Generator – Easily Create Custom Buttons with Icons and Analytics
button-generation
Design and display custom buttons anywhere on your site. Add floating or inline buttons with icons, advanced targeting, and built-in analytics.
Floating Button – Easily Create Sticky, Fixed & Floating Buttons
floating-button
Floating Buttons let you easily create sticky, fixed, and floating action buttons
Bubble Menu – Floating Button Menu with Sticky Navigation
bubble-menu
Create interactive floating bubble menus to enhance site navigation and boost user engagement effortlessly.
Floating Form Button Developer Profile
14 plugins · 18K total installs
How We Detect Floating Form Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-form-button/assets/css/bubble.css/wp-content/plugins/floating-form-button/admin/assets/css/style.css/wp-content/plugins/floating-form-button/assets/css/style.css/wp-content/plugins/floating-form-button/assets/js/script.js/wp-content/plugins/floating-form-button/assets/js/script.jsfloating-form-button/assets/css/bubble.css?ver=floating-form-button/admin/assets/css/style.css?ver=floating-form-button/assets/css/style.css?ver=floating-form-button/assets/js/script.js?ver=HTML / DOM Fingerprints
wb_ffb_menu_pagewb_ffb_bubble_containerwb_ffb_buble_boxwb_ffb_bubblewb_ffb_bubble_square_bottom_leftwb_ffb_bubble_square_bottom_rightwb_ffb_bubble_square_bottom_plainwb_ffb_bubble_round_bottom_left+3 morename="wb_ffb_form_shortcode"name="wb_ffb_bubble_style"name="wb_ffb_custom_css"